Privacy Policy
OFORO LTD is the data controller for personal data you provide to nxted.ai. This policy explains what we collect, how we use it, and your rights under the UK GDPR, EU GDPR, and India's Digital Personal Data Protection Act 2023.
1. Controller identity and contacts
Data Controller: OFORO LTD, Company No. 16787568, registered office at Unit 8 Lyon Road, Milton Keynes, England, MK1 1EX. ICO registration: pending.
Data Protection Officer (DPO): dpo@nxted.ai. Appointed under Article 37 UK GDPR because our core processing includes large-scale processing of Article 9 special category data (biometric data via Nxted Capture).
EU Representative (Article 27 EU GDPR): contact details published on this page once appointed; in the meantime EU data subjects may contact our DPO.
2. Controller / Processor split
Our role depends on the data set:
- Controller for: contributor and contributor-applicant data; capture-subject footage; Client account holders' contact data; website visitor analytics.
- Processor for: personal data embedded in Client uploads to Expert evaluation (e.g. names or identifiers contained in the AI outputs the Client asks us to evaluate). The terms in the Data Processing Agreement govern that processing.
3. Categories of personal data we process
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email, password hash, role, company | You |
| Contributor profile | CV, expertise, languages, hourly rate, capacity | Contributor |
| KYC / payments | Bank or UPI account details, tax ID, ID verification | Contributor / payments provider |
| Capture footage | Egocentric video, audio, hand-pose, biometric data | Capture subject (consent) |
| Client-uploaded data | AI outputs, prompts; may contain personal data | Client (we are processor) |
| Usage and security | Logs, IP, device, cookie identifiers | Automated |
4. Lawful bases
We rely on the following lawful bases under Article 6 UK GDPR:
- Contract (Art 6(1)(b)) - to deliver the Services to Clients and engage Contributors.
- Legitimate interests (Art 6(1)(f)) - for service improvement, fraud prevention, security, and limited analytics. Our balancing assessment is available on request.
- Legal obligation (Art 6(1)(c)) - to comply with tax, accounting, anti-money-laundering and other statutory duties.
- Consent (Art 6(1)(a) + Art 9(2)(a)) - for biometric footage collected via Nxted Capture, and for non-essential cookies.
5. Special category data - Capture footage
Egocentric video collected through Nxted Capture is treated as Article 9 UK GDPR special category data from the moment of capture. Our lawful basis is the data subject's explicit consent (Article 9(2)(a) UK GDPR and section 6 of India's DPDP Act 2023).
Capture consent process
- Each subject signs a written consent notice in English and their regional language before any filming begins.
- The notice explains the purpose, recipients, retention period, and the right to withdraw consent at any time for future processing.
- A signed Data Protection Impact Assessment (DPIA) under Article 35 UK GDPR is required for every Capture programme.
- Withdrawal of consent halts further processing of the subject's data and triggers deletion within 90 days, except where the data has been irreversibly anonymised or licensed to a Client before withdrawal.
6. How we use personal data
- To deliver the Services and onboard you to projects.
- To match Contributors with suitable projects.
- To process payments and meet our tax obligations.
- To detect, investigate and prevent fraud, abuse, and security incidents.
- To respond to data subject requests, legal claims and regulator enquiries.
- To improve our services (anonymised metadata only; we do not train AI models on identifiable personal data).
7. Retention
| Data | Retention |
|---|---|
| Client account data | Duration of the contract plus 6 years (UK statutory limitation for contract claims, s.5 Limitation Act 1980) |
| Contributor profile | Duration of engagement plus 24 months; longer if required by Indian tax law (typically 8 years for invoice records) |
| Contributor applicants - rejected | 90 days, then deletion |
| Raw Capture footage | Term of the Client licence; deleted within 90 days of expiry unless explicit re-consent is given |
| Audit logs | 12 months (security and accountability) |
| Anonymised metadata | Indefinite, no identification possible |
8. Your rights
Under the UK GDPR and EU GDPR you have the right to:
- Access your personal data (Article 15)
- Rectify inaccurate data (Article 16)
- Erase your data where the legal grounds apply (Article 17)
- Restrict processing (Article 18)
- Data portability (Article 20)
- Object to processing, including profiling (Article 21)
- Not be subject to a solely automated decision with legal or similarly significant effect (Article 22) - note our matching engine is decision-support, not solely automated
- Withdraw consent at any time, where consent is the lawful basis (Article 7(3))
Send requests to dpo@nxted.ai. We respond within one month (extendable to three for complex requests, with notice). We will verify your identity before responding. There is no fee unless the request is manifestly unfounded or excessive.
9. International transfers
The Services are delivered from the United Kingdom with a contributor network in India. This means we transfer personal data:
- From the UK to India - protected by the UK International Data Transfer Agreement (IDTA) issued under section 119A of the Data Protection Act 2018.
- From the EU to the UK - protected by the European Commission adequacy decision for the UK (28 June 2021, renewed 2025).
- From the EU to India - protected by EU Standard Contractual Clauses (Commission Decision 2021/914) with the UK Addendum where applicable.
- From the UK or EU to the US - only where the recipient is on the EU-US Data Privacy Framework or subject to UK SCCs.
A copy of the relevant transfer mechanism and our Transfer Risk Assessment is available on request to dpo@nxted.ai.
10. Security
We apply the technical and organisational measures described in our Security Whitepaper, including encryption at rest (AES-256) and in transit (TLS 1.3), mandatory MFA, role-based access control, network segmentation between application and biometric data stores, and regular penetration testing.
We notify the ICO of personal data breaches within 72 hours where required by Article 33 UK GDPR, and notify affected data subjects without undue delay where Article 34 applies.
11. Cookies
See our Cookie Policy for details and to manage your preferences.
12. Children
The Services are not directed at children. Contributors must be at least 18 years old. We do not knowingly collect data of minors; please contact our DPO if you believe we have.
13. Complaints
If you have a concern, please contact our DPO first. You also have the right to lodge a complaint with a supervisory authority:
- UK: Information Commissioner's Office (ico.org.uk), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
- EU: your local supervisory authority (list at edpb.europa.eu).
- India: the Data Protection Board of India, under the DPDP Act 2023.
14. Changes
We may update this policy. Material changes are notified by email at least 14 days before they take effect. The version history is available at the foot of this page on request.
OFORO LTD · Registered in England & Wales · Company No. 16787568 · Unit 8 Lyon Road, Milton Keynes, England, MK1 1EX
Questions: legal@nxted.ai · DPO: dpo@nxted.ai